Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Palo Alto Networks
Exam Format
Registration
Validity
PCCNSA Exam Topics and Domains
PCCNSA is organized into 4 weighted domains. Expect to work with Strata Cloud Manager, Next-Generation Firewall, PAN-OS, SD-WAN, and more.
Object Configuration Creation and Application
Security Profiles and Security Profile Groups
- Understand how to create and configure security profiles
- Apply security profiles to security policies
- Create and manage security profile groups
Decryption Profiles
- Configure decryption profiles for SSL/TLS inspection
- Apply decryption profiles to decryption policies
External Dynamic Lists
- Create external dynamic lists from various sources
- Apply EDLs to security and decryption policies
Custom Objects
- Create custom objects including URL categories, signatures, and data patterns
- Apply custom objects to appropriate security policies
Log Forwarding Profiles
- Configure log forwarding profiles for different log types
- Integrate with Strata Logging Service and external SIEM systems
Data Security Profiles
- Configure data security profiles to prevent data leakage
- Apply data patterns and file blocking rules
IoT Security Profiles
- Configure IoT security profiles
- Apply IoT security policies to protect IoT devices
DoS Protection Profiles
- Configure DoS protection profiles
- Apply DoS protection to security zones and policies
SD-WAN Profiles and Templates
- Configure SD-WAN profiles and templates
- Apply SD-WAN configurations across multiple devices
Policy Creation and Application
Security Policies
- Create security policies using App-ID, User-ID, and Content-ID
- Apply appropriate security profiles to policies
- Understand policy evaluation order and best practices
Decryption Policies
- Configure decryption policies for SSL/TLS traffic inspection
- Implement decryption exemptions for sensitive traffic
Application Override Policies
- Configure application override policies for custom applications
- Understand when application override is necessary
Policy-Based Forwarding (PBF) Policies
- Configure PBF policies for advanced traffic routing
- Understand PBF use cases and scenarios
SD-WAN Routing and SLA Policies
- Configure SD-WAN routing policies for optimal path selection
- Create SLA policies to ensure application performance
Management and Operations
Centralized Management System
- Navigate and use Strata Cloud Manager for centralized management
- Configure folders, snippets, and automations
- Utilize Strata Logging Service for log management
Security Posture Improvement
- Use Command Center, Activity Insights, and Policy Optimizer to improve security posture
- Implement security recommendations and optimize policies
Incident Remediation
- Use Log Viewer and Incidents/Alerts page to investigate and remediate security incidents
- Perform effective log analysis for incident response
Troubleshooting
Configuration Troubleshooting
- Identify and resolve common configuration errors
- Understand differences between on-box and cloud management troubleshooting
Runtime and Commit/Push Errors
- Diagnose and resolve runtime errors
- Troubleshoot commit and push failures in Strata Cloud Manager
Device Usage and Health
- Monitor and troubleshoot device resource usage
- Identify and resolve device health issues
How do I earn this certification?
Passing PCCNSA earns the Palo Alto Networks Certified Network Security Analyst certification. It sits in the Network Security track.
- PCCNSA - Network Security Analyst
- PCNSE - Next-Generation Firewall Engineer
- PCSAE - SD-WAN Engineer
- PCSFE - Security Service Edge Engineer
- PCNSE - Next-Generation Firewall EngineerDeeper expertise in PAN-OS and NGFW deployment
- PCSAE - SD-WAN EngineerSD-WAN deployment and management specialization
- PCSFE - Security Service Edge Engineer SASE and SSE deployment expertise
- PCCSE-XA - XSIAM AnalystTransition to Security Operations Center (SOC) analyst role
- PCCSE-XDR - XDR AnalystExtended detection and response specialization
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
Use the official PlanetCert Practice Test alongside the study plan below to prepare efficiently for PCCNSA.
What's changed on this exam?
- ACTIVE
- Last content update: 2025-08-01
- Announcement date: 2025-03-01
- Strata Cloud Manager Latest Central platform for Network Security Analyst exam • Release date: 2025-03-31
- Strata Logging Service Latest Cloud-based logging integration covered in exam • Release date: 2025-01-01
- PAN-OS 11.x Latest firewall OS features and capabilities • Release date: 2024-11-01
Who should take this exam?
- Hands-on experience with Palo Alto Networks technologies
- Basic understanding of network security concepts
- Familiarity with firewall administration
- Experience with Strata Cloud Manager or Panorama